Skip to main content
Back to Research
Agentic AI & Critical Infrastructure
2026

Agentic AI Systems for Autonomous Prevention, Detection, and Mitigation of Cyber Attacks in Critical Infrastructure: A Structured Literature Review

Hasta Bahadur Chhetri
La Grandee International College, Pokhara, Gandaki Province, Nepal
E-mail: mail@bimql.link, PMID: N/A doi: 10.5281/zenodo.agentic-ai

AI Summary  This paper presents a PRISMA-informed structured review of 26 selected studies (23 peer-reviewed articles and 3 preprints) on agentic AI systems for autonomous prevention, detection, and mitigation of cyberattacks across industrial control systems, IoT networks, and smart agriculture. The review classifies techniques across the NIST Cybersecurity Framework, proposes a five-generation taxonomy, and finds that while detection-focused systems achieve accuracies exceeding 93%, autonomous recovery and field-validated agricultural IoT deployments remain severely underserved.

Abstract:

The escalating frequency and sophistication of cyber attacks targeting critical infrastructure—including energy grids, water systems, transportation networks, and agricultural IoT—have outpaced the capabilities of traditional signature-based and rule-driven defense mechanisms. This paper presents a structured, PRISMA-informed literature review of agentic AI systems for autonomous prevention, detection, and mitigation of such attacks. A structured review of 26 selected studies (23 peer-reviewed articles and 3 preprints) was conducted, spanning agentic AI architectures, industrial control system security, agricultural IoT cybersecurity, reinforcement learning, multi-agent defense, and LLM-based threat detection. The analysis reveals that the current state of the art is characterized by modular multi-agent LLM architectures achieving a reported system-wide detection accuracy of 93.6%, SARSA-based reinforcement learning honeypots exceeding 0.99 accuracy for ICS intrusion detection, and autonomous frameworks enabling real-time incident response and adaptive threat hunting. However, significant gaps persist: 18 of 26 reviewed papers are literature reviews, position papers, or conceptual proposals lacking original empirical validation; only a minority evaluate techniques in operational environments; recovery automation is addressed by a single study; and agricultural IoT remains severely underserved with no field-validated deployments. The study concludes that while agentic AI offers considerable potential for critical infrastructure cyber defense, the field must transition from conceptual frameworks to large-scale empirical validation, standardized evaluation methodologies, and expanded coverage of the NIST Cybersecurity Framework's Identify and Recover functions. Concrete recommendations are provided for deploying semi-autonomous multi-agent systems in security operations centers, integrating reinforcement learning-enhanced honeypots with defense-in-depth strategies, and prioritizing research into autonomous recovery and longitudinal adaptability testing.

Introduction

The frequency and sophistication of cyber attacks targeting critical infrastructure have escalated substantially in recent years. Industrial Control Systems (ICS), Internet of Things (IoT) networks, and agricultural systems—once considered secure by virtue of air-gapped isolation—are increasingly exposed to sophisticated adversaries. Landmark incidents such as Stuxnet's destruction of approximately 1,000 uranium enrichment centrifuges, BlackEnergy3's compromise of the Ukrainian power grid affecting nearly 250,000 customers, and the Colonial Pipeline ransomware attack that caused fuel shortages across the eastern United States illustrate the scale of the threat [1].

The convergence of operational technology with information technology during Industry 4.0 has expanded the attack surface, introducing legacy ICS vulnerabilities into internet-connected environments [2]. In smart agriculture, IoT devices deployed for soil monitoring, irrigation control, and autonomous farming machinery operate with minimal security provisions, making them susceptible to man-in-the-middle attacks, data breaches, and device tampering [3], [4]. The global AI-in-cybersecurity market, valued at $24.8 billion in 2024 and projected to reach $146.5 billion by 2034, reflects the urgency of developing advanced defenses [5].

Traditional cybersecurity methods—signature-based intrusion detection, rule-based firewalls, and manual incident response—are fundamentally reactive. These approaches depend on predefined threat signatures, offline analysis, and continuous human supervision [6]. As attack vectors grow more sophisticated, human-centered security operations centers face alert fatigue, delayed response times, and an inability to coordinate across heterogeneous threat surfaces [5], [7]. In contrast, autonomous agentic AI systems offer proactive, independent action: continuously monitoring traffic, autonomously triaging and correlating alerts across multiple domains, and executing containment measures without awaiting human instruction [8], [9].

This paper presents a structured, PRISMA-informed literature review of agentic AI systems for autonomous cyber attack prevention, detection, response, and mitigation across three critical domains: Industrial Control Systems, IoT networks, and agricultural systems. While existing literature has addressed individual aspects of autonomous cybersecurity, significant gaps remain in cross-domain synthesis and in mapping agentic capabilities to the complete cybersecurity lifecycle. This review bridges those gaps by examining 26 selected studies (23 peer-reviewed and 3 preprints), classifying techniques across the NIST Cybersecurity Framework's five core functions (Identify, Protect, Detect, Respond, and Recover) [12], and evaluating approaches across dimensions of effectiveness, domain applicability, feasibility, scalability, and adaptability.

Review Methodology

This study was conducted as a structured literature review with reporting aligned to the PRISMA 2020 principles of transparency and reproducibility. It is deliberately positioned as a structured analytical review rather than an exhaustive systematic review with meta-analysis: because the reviewed techniques are heterogeneous and evaluated on incompatible datasets, the objective is a cross-domain analytical synthesis of how agentic and autonomous AI techniques map onto the cyber-defense lifecycle for critical infrastructure, not a pooled estimate of a single effect.

Research Questions

The review was guided by four research questions:

  1. RQ1. Which agentic and autonomous AI techniques have been proposed for the prevention, detection, response, and mitigation of cyber attacks in critical infrastructure?
  2. RQ2. How do these techniques map onto the five core functions of the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover)?
  3. RQ3. How do the techniques compare across effectiveness, domain applicability, feasibility, scalability, and adaptability, and what is the quality of the supporting evidence?
  4. RQ4. Which domain-specific gaps, particularly in ICS/SCADA and agricultural IoT, remain open for future research?

Search Strategy

Five bibliographic sources were searched: IEEE Xplore, ACM Digital Library, Scopus, arXiv, and Google Scholar, covering publications from January 2018 to May 2026. The lower bound captures the emergence of deep-learning and reinforcement-learning approaches to industrial-control-system security; foundational pre-2018 incidents such as Stuxnet are cited for context but were not eligible as reviewed studies. Search queries combined three concept groups with Boolean operators: an agent/autonomy group, a cyber-defense group, and a domain group. Backward and forward snowballing on the most-cited included papers was used to recover relevant studies not surfaced by keyword search.

Study Selection

Records were screened against explicit criteria following the PRISMA stages of identification, screening, eligibility, and inclusion. A study was included if it (1) addressed autonomous or semi-autonomous AI techniques (agentic AI, multi-agent systems, reinforcement learning, or LLM-based agents) applied to cybersecurity; (2) targeted at least one relevant domain (general critical infrastructure, ICS/SCADA, network/IoT, or agricultural IoT); (3) was a peer-reviewed journal article, conference paper, or a citable preprint by identifiable authors; and (4) was written in English.

The database searches returned approximately 410 records, reduced to roughly 300 after duplicate removal. These were screened by title and abstract, and about 80 candidates advanced to full-text assessment. A final corpus of 26 studies was retained for in-depth analysis.

PRISMA-style Study-Selection FlowIdentification≈410 records identified(5 databases + snowballing)After duplicate removal≈300 recordsScreening≈300 records title/abstract assessedExcluded ≈220(no AI component; no CI focus)Eligibility≈80 full-text articles assessedExcluded 54(non-archival; superseded)Included26 studies analyzedFig. 1. PRISMA-style study-selection flow (approximate counts).

Quality Appraisal and Data Extraction

Each study was appraised on three dimensions: (i) evidence type, distinguishing five levels of strength: literature or narrative review, conceptual framework or position paper, simulation/benchmark study, proof-of-concept prototype, and real operational deployment; (ii) validation level, whether operational deployment, simulation/benchmark dataset, projected/illustrative, or none; and (iii) venue type, whether an indexed journal, peer-reviewed conference proceedings, or preprint/technical report.

Thematic AreaPapersEmpirical / PoCReview / Conceptual
Agentic AI in cybersecurity716
ICS and critical infrastructure615
Agricultural IoT security413
RL & multi-agent defense532
LLM-based agents202
Honeypot-based deception defense220
Total26818
Table 1. Reviewed corpus by thematic area and evidence type.
Evidence LevelCount
Literature / narrative review14
Conceptual framework / position paper4
Simulation / benchmark dataset5
Proof-of-concept prototype2
Real operational deployment1
Table 2. Strength of evidence per reviewed study.

Threats to Validity

This review is subject to several limitations. Selection bias may arise from the choice of databases and search terms; snowballing was used to mitigate, but some relevant work may be absent. Language restriction to English may exclude pertinent non-English studies. Inclusion of preprints introduces sources that have not completed peer review; these are explicitly flagged and down-weighted. Finally, the heterogeneity of evaluation methods across the corpus precludes a quantitative meta-analysis, which is why a structured analytical synthesis was adopted.

Background and Theoretical Foundations

AI Agents and Agentic AI

An AI agent is defined as an autonomous computational entity that perceives its environment, reasons about its goals, and executes actions to achieve those goals without continuous human intervention. Agentic Artificial Intelligence (AAI) extends this concept further: it refers to systems that are autonomous, adaptable, and goal-directed, capable of proactive decision-making in dynamic environments [10]. Unlike traditional reactive AI systems, which produce single-shot outputs in response to specific prompts, agentic AI introduces persistent state, tool use, and self-directed control loops that enable planning, action, and revision across long-lived, multi-step workflows [6].

To make the scope of this review precise, a system is treated as agentic only when it exhibits all five of the following properties: (i) goal-directed behavior, pursuing an objective rather than answering a single query; (ii) planning over multiple steps toward that objective; (iii) persistent memory that carries state across steps; (iv) tool use, invoking external tools, data sources, or APIs; and (v) autonomous action, executing decisions without step-by-step human prompting.

Vinay [11] traces a five-generation taxonomy of agentic AI in cybersecurity, from single-model LLM reasoners through tool-augmented agents to distributed multi-agent systems and semi-autonomous investigative pipelines. Security operations centers (SOCs) increasingly adopt these systems because multi-stage reasoning (triage, enrichment, threat intelligence lookup, hypothesis building, evidence correlation, escalation, and reporting) is inherently a multi-agent coordination problem [5], [11].

ReactiveAutonomousTraditional AIrule-based, static logicMachine Learningpattern learning, single-shotRLreward-driven, autonomousLLM Agentsreasoning + tool useMulti-Agentcoordinated, distributedAgentic AIgoal-directed, planning,memory, tool use, autonomyStaticReactiveSelf-actionReasoningCoordinationFull agencyFig. 2. Conceptual taxonomy situating agentic AI among related system classes, ordered left to right by increasing autonomyand reasoning complexity. Agentic AI combines all five properties: goal-directed behavior, planning, persistent memory, tool use, and autonomous action.

Cybersecurity Functions

The NIST Cybersecurity Framework (CSF) provides a structured taxonomy for organizing cybersecurity capabilities into five core functions: Identify, Protect, Detect, Respond, and Recover [5], [12]. The Identify function encompasses understanding organizational context, assets, and risks. Protect implements safeguards such as network segmentation, access control, and patch management. Detect addresses timely discovery of cybersecurity events through continuous monitoring and automated triage. Respond covers action on a detected incident, including autonomous quarantine and containment. Recover involves restoring capabilities impaired by a cybersecurity event—the frontier of autonomous self-healing systems. Throughout this study, the term mitigation is treated as spanning the Respond and Recover functions.

Industrial Control Systems (ICS)

ICS encompasses SCADA systems, Distributed Control Systems (DCS), and Programmable Logic Controllers (PLC), which together regulate critical infrastructure sectors including energy, water, manufacturing, transportation, and power generation [1], [18]. Historically air-gapped, the convergence of OT with IT during Industry 4.0 brought legacy ICS vulnerabilities—insecure protocols, remote connections, lack of authentication—into internet-connected environments [1]. The CIA triad priorities differ in OT: availability takes precedence over confidentiality and integrity because of the criticality of continuous industrial operations [20].

Agricultural IoT and Smart Agriculture

Smart agriculture uses IoT-based wireless sensors, big data analytics, AI, and machine learning to monitor and manage crop cultivation, livestock management, soil health, and resource utilization [3], [21]. IoT devices in smart agriculture are often vulnerable due to lack of standardization, weak authentication mechanisms, and infrequent firmware updates, making them prime targets for man-in-the-middle attacks, DDoS, data breaches, and unauthorized access [3]. Unlike traditional IT, smart agriculture security must also account for physical consequences: a compromised irrigation controller can destroy crops, a manipulated pesticide drone can cause environmental harm, and falsified sensor data can lead to catastrophic farming decisions [3], [4].

Agentic-AI Cyber-Defense PipelineThreat inputMonitoringDetectionPlanningResponseRecoverycontinuous feedback and learning (Detect → Respond → Recover)
Fig. 3. Synthesized agentic-AI cyber-defense pipeline. Specialized monitoring, detection, planning, and response agents share persistent memory, tool access, and goal-directed autonomy, driving an automated recovery process.

Literature Review

This section presents a structured review of the literature across six thematic areas relevant to agentic AI for autonomous cyber attack prevention, detection, and mitigation in critical infrastructure.

Agentic AI in Cybersecurity

Adabara et al. [10] provide a comprehensive narrative review of Agentic Artificial Intelligence (AAI) in cybersecurity, synthesizing literature from 2005 to 2025 across three thematic pillars: cognitive autonomy, ethical governance, and quantum-resilient defense. Lazer et al. [6] present a survey examining the dual-use implications of agentic AI for cybersecurity, identifying that agentic capabilities enable continuous monitoring, autonomous incident response, adaptive threat hunting, and fraud detection at scale—while the same properties amplify adversarial power. Three representative use-case implementations demonstrate how agentic AI behaves in practical cybersecurity workflows.

Vinay [11] traces a five-generation taxonomy of agentic AI in cybersecurity, from single-model LLM reasoners through tool-augmented agents to distributed multi-agent systems and semi-autonomous investigative pipelines. Kshetri [5] investigates the potential of agentic AI in cybersecurity, examining real-world deployments at Darktrace, CrowdStrike, ReliaQuest, and Twine, and reports the global AI-in-cybersecurity market was valued at $24.8 billion in 2024, projected to reach $146.5 billion by 2034. Mohammed [8] explores agentic AI as a proactive cybercrime sentinel for detecting and deterring social engineering attacks. Sheth et al. [9] present AI-driven self-healing cybersecurity systems augmented with agentic AI for adaptive threat response and resilience—the sole work directly addressing autonomous recovery. Shrestha et al. [16] investigate cybersecurity bottlenecks of AI agents in industrial automation through a PRISMA-informed review combined with simulation-based analysis.

ICS and Critical Infrastructure Security

Nankya et al. [18] present a comprehensive review of ICS security covering components (SCADA, DCS, PLC), protocols, and machine-learning-driven defense strategies. Koay et al. [1] survey the vulnerability picture in ICS and evaluate ML-based detection methods, documenting that Industry 4.0 convergence has brought IT vulnerabilities into OT systems. Aslam et al. [19] provide a systematic review of AI for secure and sustainable industrial control systems, covering ML, deep learning, LLMs, and cloud computing across 250 articles. Pinto et al. [2] survey ML-based intrusion detection systems for critical infrastructure, finding that most evaluations rely on datasets (KDD-99, NSL-KDD) that do not represent real critical-infrastructure traffic. Dehghantanha et al. [22] present a position paper analyzing challenges and opportunities in autonomous cybersecurity, discussing RL as a central approach. Paulraj et al. [12] propose a hybrid AI-driven cybersecurity framework with projected improvements: breach containment time reduced from 280 to 0.5 days, detection accuracy increased from 60% to 95%, and false positives reduced from 30% to 2%.

Agricultural IoT Security

Adewusi et al. [3] review cybersecurity challenges in IoT-driven smart agriculture, identifying threats including MITM attacks, DDoS, data breaches, and physical tampering. Demestichas et al. [4] conduct a thorough survey of security threats in agricultural IoT and smart farming, concluding that the agricultural sector tends to be more vulnerable than other sectors adopting digital tools. Qazi et al. [21] provide a critical review of IoT and AI technologies in smart agriculture, covering hardware, AI applications, and deployment challenges. Davcev et al. [15] propose the only agentic AI-based IoT precision agriculture framework, formalizing coordination within a Multi-Agent Partially Observable Markov Decision Process (MPOMDP) perspective. The framework remains at proof-of-concept stage without field validation.

Reinforcement Learning and Multi-Agent Defense

Landolt et al. [7] survey Multi-Agent Reinforcement Learning (MARL) applications for automated cyber defense, focusing on intruder detection and lateral movement containment. Sewak et al. [17] review Deep Reinforcement Learning (DRL) applications in cybersecurity, covering network anomaly detection and defense against advanced metamorphic malware. Javadpour et al. [23] propose DMAIDPS, a distributed multi-agent intrusion detection and prevention system for cloud IoT environments, evaluated on KDD Cup 99 and NSL-KDD with improvements of 16.81% in recall, 16.05% in accuracy, and 18.12% in F-score. Louati et al. [24] introduce Big-IDS, a decentralized multi-agent RL approach for distributed intrusion detection in big data networks. Hmimou et al. [13] present a modular multi-agent architecture integrating specialized agents (email verification, log analysis, IP scanning) with LLMs, achieving system-wide detection accuracy of 93.6%, multi-agent correlation accuracy of 87%, and false positive reduction of 41.3% on CIC-IDS 2017 and SpamAssassin datasets.

LLM Agents in Cybersecurity

Xu et al. [25] conduct the most extensive survey, systematically analyzing 185 papers from over 40,000 initially collected publications, identifying that LLMs are being applied to vulnerability detection, malware analysis, and network intrusion detection. A significant emerging trend is the use of LLM-based autonomous agents, representing a shift from single-task execution to orchestrating complex multi-step security workflows. Panwar and Abdelrahman [26] present a conference review of agentic AI in cybersecurity focusing on autonomous threat detection and adaptive defense mechanisms.

Honeypots and Deception-Based ICS Defense

Mesbah et al. [20] analyze ICS and SCADA system attacks using the Conpot honeypot to simulate real ICS/SCADA systems, emphasizing defense-in-depth for OT operators. Pashaei et al. [14] propose a SARSA reinforcement learning honeypot targeting DDoS and MITM attacks in industrial control networks, achieving accuracy exceeding 0.99 and F-measure of 0.98—the highest reported performance of any reviewed paper.

Research Analysis & Taxonomy

Table 3 presents a taxonomic classification of all 26 reviewed papers across domain, primary cybersecurity function, AI technique, autonomy level, and evaluation approach.

Author & YearDomainFunctionTechniqueAutonomy
Adabara et al. [10]GeneralDetect, RespondAgentic AIFull
Adewusi et al. [3]Agri-IoTPrevent, DetectMLAssisted
Aslam et al. [19]ICSDetect, RespondML, DL, LLMSemi
Davcev et al. [15]Agri-IoTPrevent, ResponseMulti-agent, MPOMDPFull
Dehghantanha et al. [22]GeneralDetect, RespondRL, MLFull
Demestichas et al. [4]Agri-IoTPrevent, DetectICT threat surveyAssisted
Hmimou et al. [13]NetworkDetectMulti-agent, LLMSemi
Javadpour et al. [23]NetworkDetect, PreventMulti-agentSemi
Koay et al. [1]ICSDetectMLAssisted
Kshetri [5]GeneralDetect, RespondAgentic AIFull
Landolt et al. [7]NetworkDetect, RespondMulti-agent RLFull
Lazer et al. [6]GeneralDetect, RespondAgentic AI, LLMFull
Louati et al. [24]NetworkDetectMulti-agent RLFull
Mesbah et al. [20]ICSDetectHoneypot (Conpot)Assisted
Mohammed [8]GeneralPrevent, DetectAgentic AIFull
Nankya et al. [18]ICSPrevent, DetectMLAssisted
Panwar & Abdelrahman [26]GeneralDetectAgentic AIFull
Pashaei et al. [14]ICSDetectRL (SARSA), HoneypotSemi
Paulraj et al. [12]ICSDetect, ResponseHybrid AIFull
Pinto et al. [2]ICS/CIDetectML (IDS)Assisted
Qazi et al. [21]Agri-IoTPreventML, DLAssisted
Sewak et al. [17]NetworkDetect, ProtectDeep RLSemi
Sheth et al. [9]GeneralDetect, Respond, RecoverAgentic AI, RLFull
Shrestha et al. [16]ICSDetectMulti-agentSemi
Vinay [11]GeneralDetect, RespondLLM, Multi-agentSemi–Full
Xu et al. [25]GeneralDetect, PreventLLMAssisted–Semi
Table 3. Taxonomic classification of the 26 reviewed papers.

Dominant Patterns

Detection is the most frequently addressed cybersecurity function, appearing as a primary function in 24 of 26 papers (92%). Response functions appear in 10 papers (38%), protection/prevention in 9 (35%), and recovery in only 1 paper (4%). Of the 26 papers, 18 (69%) are literature reviews, position papers, or conceptual proposals rather than original empirical studies. Only 8 papers provide original empirical evidence, and just one reports a real operational deployment.

NIST CSF Function Coverage (Primary)242010024Detect10Respond9Protect1Recover0IdentifyFig. 4. Coverage of NIST Cybersecurity Framework functions (primary-function counts).

AI Technique and Domain Distribution

Machine learning is the most prevalent technique, appearing in 21 papers (81%). Within this, RL variants (deep RL, multi-agent RL, SARSA) are the most common specific technique in 8 papers (31%). Agentic AI is explicitly addressed in 10 papers (38%), LLM-based approaches in 5 papers (19%), and honeypot-based techniques in 2 papers (8%). Domain distribution: General cybersecurity leads with 9 papers (34.6%), followed by ICS with 8 (30.8%), network-specific with 5 (19.2%), and agricultural IoT with 4 (15.4%).

Autonomy Level Trends

The autonomy level skews toward full autonomy on paper: 11 papers (42%) propose fully autonomous systems, 6 (23%) semi-autonomous, and 7 (27%) human-assisted, with 2 spanning categories. However, most full-autonomy papers are conceptual or survey-based rather than empirically validated. Among papers with empirical results, Hmimou et al. [13] and Pashaei et al. [14] operate at semi-autonomous levels, suggesting that practical systems still require human oversight for high-stakes decisions.

Evaluation of Techniques

This section evaluates the reviewed techniques across five dimensions—effectiveness, domain applicability, feasibility, scalability, and adaptability—followed by domain-specific insights and integration with the NIST Cybersecurity Framework.

Effectiveness

Detection accuracy varies substantially across techniques and domains. Hmimou et al. [13] report 93.6% system-wide detection accuracy with 87% multi-agent correlation accuracy and 41.3% false positive reduction on CIC-IDS 2017 and SpamAssassin datasets. Pashaei et al. [14] achieve the highest reported accuracy, exceeding 0.99 with an F-measure of 0.98, using a SARSA-based RL honeypot for ICS networks. Paulraj et al. [12] project improvements including 98% reduction in false positives and 97.6% reduction in downtime.

PaperRL VariantDomainAccuracyKey StrengthKey Limitation
Pashaei et al. [14]SARSA (on-policy)ICS>0.99Highest accuracy; dual-agent designLimited to DDoS/MITM scenarios
Hmimou et al. [13]Multi-agent + LLMNetwork93.6%Cross-domain correlation; explainableLLM-augmented; not pure RL
Landolt et al. [7]MARL (surveyed)NetworkVariableDecentralized coordination; Cyber GymsSim-to-real gap; high-dim. spaces
Sewak et al. [17]Deep RL (surveyed)NetworkState-of-artMetamorphic malware defenseSurvey only; no experiments
Table 4. Detection accuracy across RL-based systems.

Domain-Specific Insights

ICS and Critical Infrastructure. Pashaei et al. [14] achieve the highest reported performance with their SARSA-RL honeypot system. Mesbah et al. [20] deploy Conpot and collect real attacker behavior data. Paulraj et al. [12] project a reduction in breach containment from 280 to 0.5 days. Pinto et al. [2] caution that most ML-based IDS results stem from datasets (KDD-99, NSL-KDD) that do not represent real critical-infrastructure traffic.

PaperTechniqueAccuracyFalse Pos.Key MetricDataset
Pashaei et al. [14]SARSA-RL Honeypot>0.99F-measure: 0.98Real + simulated ICS data
Hmimou et al. [13]Multi-agent + LLM93.6%−41.3%Correlation: 87%CIC-IDS 2017, SpamAssassin
Pinto et al. [2]ML-based IDS surveyReviewedNotedIDS compilationKDD-99, NSL-KDD
Paulraj et al. [12]Hybrid AI framework95%*2%*Uptime: 99.5%*Framework analysis
Koay et al. [1]ML classifiers surveyReviewedTwo performance vectorsStuxnet, BlackEnergy
Table 5. Performance comparison of top ICS papers. (*projected values)

Agricultural IoT. Agricultural IoT security remains at an early stage compared to ICS. Adewusi et al. [3] identify vulnerabilities due to lack of standardization, weak authentication, and infrequent firmware updates. Demestichas et al. [4] provide the most comprehensive threat analysis for Agriculture 4.0. Davcev et al. [15] propose the only agentic framework specifically targeting agriculture, but it remains at proof-of-concept stage without field validation.

PaperApproachAutonomyStageKey Limitations
Davcev et al. [15]Agentic AI (MPOMDP)FullProof-of-conceptNo field validation; no physical actuation
Adewusi et al. [3]Security framework reviewAssistedConceptualNo empirical results; general best practices
Demestichas et al. [4]Agri-IoT threat surveyAssistedLiterature reviewNo novel framework or experimental data
Qazi et al. [21]IoT/AI tutorial reviewAssistedSurveyNo security-specific focus; technology survey
Table 6. Agricultural IoT technique comparison.

Cross-Cutting Limitations

Several cross-cutting limitations emerge. First, the field relies excessively on survey and review papers (18 of 26). Second, among papers that do report empirical results, evaluation is conducted on benchmark datasets or simulated environments rather than operational critical infrastructure. Third, scalability to large infrastructure is unaddressed—none of the reviewed papers evaluate performance at enterprise or national infrastructure scale. Fourth, adaptability to novel attack patterns is claimed as a strength but never empirically demonstrated. Fifth, agricultural IoT is severely underserved relative to both its economic importance and its vulnerability surface.

CategoryPapersPrimary Limitations
Agentic AI SurveysAdabara, Lazer, Vinay, KshetriNo empirical validation; conceptual only; dual-use risks unquantified
ICS/CI SystemsNankya, Koay, Aslam, Pinto, PaulrajMostly surveys; projected metrics unvalidated; sim-to-real gap; legacy protocols
Agricultural IoTAdewusi, Demestichas, Qazi, DavcevPoC only; no field deployment; resource-constrained devices; rural connectivity
RL/Multi-AgentLandolt, Sewak, Louati, HmimouSim-to-real unproven; high-dim. state spaces; single-domain focus
LLM-based AgentsXu, Vinay, PanwarLimited datasets; hallucination risks; no real-time validation; prompt injection
Honeypot / DeceptionMesbah, PashaeiLimited coverage (DDoS/MITM only); fingerprinting risk; regional bias
Table 7. Summary of limitations per paper category.

Integration with the NIST CSF

The Detect function is well served: Hmimou et al. [13], Pashaei et al. [14], and the ML approaches reviewed by Pinto et al. [2] and Koay et al. [1] provide strong detection capabilities. The Protect function benefits from prevention-oriented frameworks by Nankya et al. [18] and Adewusi et al. [3]. The Respond function is partially addressed through autonomous incident response capabilities described by Sheth et al. [9] and Landolt et al. [7]. Significant gaps exist in Identify and Recover: no reviewed paper directly addresses asset management or risk assessment automation (Identify), and the Recover function is addressed only by Sheth et al. [9], whose self-healing framework remains at the conceptual stage.

Limitations of This Study

This study is subject to several limitations. First, selection bias: although a structured protocol was followed, the choice of databases and search terms may have excluded relevant work indexed elsewhere or described with different terminology; snowballing was used to mitigate this but cannot guarantee completeness. Second, language restriction: only English-language publications were considered, potentially omitting significant research published in other languages. Third, preprint inclusion: three arXiv preprints are included that have not completed peer review; these are explicitly flagged and their claims treated as indicative rather than confirmed. Finally, this is a structured analytical review without independent empirical validation—the performance figures reported are drawn from the original studies and were not independently reproduced. The heterogeneity of evaluation methods across the corpus precludes a quantitative meta-analysis.

Conclusion & Recommendations

This review conducted a structured, PRISMA-informed analysis of agentic AI systems for autonomous prevention, detection, and mitigation of cyber attacks in critical infrastructure, examining 26 selected studies (23 peer-reviewed and 3 preprints) spanning agentic architectures, ICS security, agricultural IoT, reinforcement learning, and LLM-based agents. The current state of the art is characterized by modular multi-agent LLM architectures achieving 93.6% detection accuracy [13], SARSA-based honeypot systems exceeding 0.99 accuracy for ICS intrusion detection [14], and agentic frameworks demonstrating autonomous incident response and adaptive threat hunting at scale [5], [6].

Despite these advances, significant gaps remain. Of 26 reviewed papers, 18 are literature reviews, position papers, or conceptual proposals lacking original empirical contribution. Only 4 papers evaluate techniques in operational or simulated ICS environments; none validate at enterprise or national infrastructure scale. Recovery automation is addressed by a single paper [9], and agricultural IoT security has no field-validated agentic deployments [15]. Adaptability to novel threats is universally claimed but never empirically demonstrated through longitudinal study.

Four implementation recommendations emerge: (1) deploy multi-agent LLM architectures for cross-domain threat correlation in SOC environments, prioritizing semi-autonomous operation with human-in-the-loop verification for high-impact actions [11], [13]; (2) integrate RL-enhanced honeypots with defense-in-depth strategies for ICS networks, using attack intelligence for proactive threat modeling [14], [20]; (3) align autonomous agent deployment with the NIST Cybersecurity Framework, focusing first on Detect and Respond functions while developing capacity for Identify and Recover; and (4) mandate continuous model retraining using up-to-date operational data to maintain effectiveness against evolving attack patterns [18].

Future research should prioritize: (a) large-scale empirical validation of agentic systems in operational critical infrastructure, addressing the sim-to-real transfer gap [7]; (b) standardized evaluation frameworks enabling cross-paper performance comparison across domains and techniques; (c) adaptive defense mechanisms tested longitudinally against evolving adversarial strategies to substantiate claimed adaptability; and (d) dedicated investigation of autonomous recovery and mitigation functions, which remain severely underrepresented relative to detection-focused research.

References

  1. A. M. Y. Koay, R. K. L. Ko, H. Hettema, and K. Radke, "Machine learning in industrial control system (ICS) security: Current landscape, opportunities and challenges," Journal of Intelligent Information Systems, 2023, doi: 10.1007/s10844-022-00753-1.
  2. A. Pinto, L.-C. Herrera, Y. Donoso, and J. A. Gutierrez, "Survey on intrusion detection systems based on machine learning techniques for the protection of critical infrastructure," Sensors, vol. 23, no. 5, p. 2415, 2023, doi: 10.3390/s23052415.
  3. A. O. Adewusi, N. R. Chiekezie, and N. L. Eyo-Udo, "Securing smart agriculture: Cybersecurity challenges and solutions in IoT-driven farms," World Journal of Advanced Research and Reviews, vol. 15, no. 3, pp. 480–489, 2022, doi: 10.30574/wjarr.2022.15.3.0887.
  4. K. Demestichas, N. Peppes, and T. Alexakis, "Survey on security threats in agricultural IoT and smart farming," Sensors, vol. 20, no. 22, p. 6458, 2020, doi: 10.3390/s20226458.
  5. N. Kshetri, "Transforming cybersecurity with agentic AI to combat emerging cyber threats," Telecommunications Policy, 2025, doi: 10.1016/j.telpol.2025.102976.
  6. S. J. Lazer, K. Aryal, M. Gupta, and E. Bertino, "A survey of agentic AI and cybersecurity: Challenges, opportunities and use-case prototypes," arXiv preprint, 2026, doi: 10.48550/arXiv.2601.05293.
  7. C. R. Landolt, C. Würsch, R. Meier, A. Mermoud, and J. Jang-Jaccard, "Multi-agent reinforcement learning in cybersecurity: From fundamentals to applications," in International Conference on Military Communication and Information Systems (ICMCIS), 2025. Available: https://arxiv.org/abs/2505.19837
  8. A. Mohammed, "Agentic AI as a proactive cybercrime sentinel: Detecting and deterring social engineering attacks," Journal of Data and Digital Innovation (JDDI), 2025.
  9. A. Sheth, A. Achanta, P. Matam, A. Patel, et al., "AI driven self-healing cybersecurity systems with agentic AI for adaptive threat response and resilience," in 2025 IEEE Cloud Summit, IEEE, 2025, doi: 10.1109/Cloud-Summit64795.2025.00030.
  10. I. Adabara, B. Olaniyi Sadiq, A. Nuhu Shuaibu, Y. Ibarahim Danjuma, and M. Venkateswarlu, "A review of agentic AI in cybersecurity: Cognitive autonomy, ethical governance, and quantum-resilient defense," F1000Research, vol. 14, p. 843, 2025, doi: 10.12688/f1000research.169337.1.
  11. V. Vinay, "The evolution of agentic AI in cybersecurity: From single LLM reasoners to multi-agent systems and autonomous pipelines," in International Conference on Agentic Intelligence and Cybersecurity (ICAIC), 2026, doi: 10.48550/arXiv.2512.06659.
  12. J. Paulraj, B. Raghuraman, et al., "Autonomous AI-based cybersecurity framework for critical infrastructure: Real-time threat mitigation," in 2025 IEEE/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD), IEEE, 2025, doi: 10.1109/SNPD65828.2025.11254587.
  13. Y. Hmimou, M. Tabaa, A. Khiat, and Z. Hidila, "A multi-agent system for cybersecurity threat detection and correlation using large language models," IEEE Access, 2025, doi: 10.1109/ACCESS.2025.3602681.
  14. A. Pashaei, M. E. Akbari, M. Z. Lighvan, and A. Charmin, "Early intrusion detection system using honeypot for industrial control networks," Results in Engineering, 2022, doi: 10.1016/j.rineng.2022.100576.
  15. D. Davcev, S. Kalajdziski, I. Dimitrovski, I. Kitanovski, et al., "Agentic AI-based IoT precision agriculture framework: Our vision and challenges," AgriEngineering, 2026, doi: 10.3390/agriengineering8040147.
  16. S. Shrestha, C. Banda, A. K. Mishra, F. Djebbar, and D. Puthal, "Investigation of cybersecurity bottlenecks of AI agents in industrial automation," Computers, 2025, doi: 10.3390/computers14110456.
  17. M. Sewak, S. K. Sahay, and H. Rathore, "Deep reinforcement learning in the advanced cybersecurity threat detection and protection," Information Systems Frontiers, 2023, doi: 10.1007/s10796-022-10333-x.
  18. M. Nankya, R. Chataut, and R. Akl, "Securing industrial control systems: Components, cyber threats, and machine learning-driven defense strategies," Sensors, 2023, doi: 10.3390/s23218840.
  19. M. M. Aslam, A. Tufail, H. Gul, M. N. Irshad, et al., "Artificial intelligence for secure and sustainable industrial control systems: A survey of challenges and solutions," Artificial Intelligence Review, 2025, doi: 10.1007/s10462-025-11320-9.
  20. M. Mesbah, M. S. Elsayed, A. D. Jurcut, and M. Azer, "Analysis of ICS and SCADA systems attacks using honeypots," Future Internet, 2023, doi: 10.3390/fi15070241.
  21. S. Qazi, B. A. Khawaja, and Q. U. Farooq, "IoT-equipped and AI-enabled next generation smart agriculture: A critical review, current challenges and future trends," IEEE Access, 2022, doi: 10.1109/ACCESS.2022.3152544.
  22. A. Dehghantanha, A. Yazdinejad, and R. M. Parizi, "Autonomous cybersecurity: Evolving challenges, emerging opportunities, and future research trajectories," in Autonomous Cybersecurity, ACM, 2023, doi: 10.1145/3689933.3690832.
  23. A. Javadpour, P. Pinto, F. Ja'fari, and W. Zhang, "DMAIDPS: A distributed multi-agent intrusion detection and prevention system for cloud IoT environments," Cluster Computing, 2023, doi: 10.1007/s10586-022-03621-3.
  24. F. Louati, F. B. Ktata, and I. Amous, "Big-IDS: A decentralized multi agent reinforcement learning approach for distributed intrusion detection in big data networks," Cluster Computing, 2024, doi: 10.1007/s10586-024-04306-9.
  25. H. Xu et al., "Large language models for cyber security: A systematic literature review," ACM Transactions on Software Engineering and Methodology, 2024, doi: 10.1145/3769676.
  26. S. Panwar and H. Abdelrahman, "Agentic AI in cybersecurity: Review of autonomous threat detection and adaptive defense mechanisms," in 2025 International Conference on Computer and Applications (ICCA), IEEE, 2025, doi: 10.1109/ICCA66035.2025.11431003.

How to Cite


If you reference this paper in your work, please use the following formatted citation:

H. B. Chhetri, "Agentic AI Systems for Autonomous Prevention, Detection, and Mitigation of Cyber Attacks in Critical Infrastructure: A Structured Literature Review," 2026. [Online]. Available: https://bimql.link/research/agentic-ai-cyber-defense
1